Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-10-2014 Ran by R at 2014-10-20 10:27:26 Run:1 Running from C:\Documents and Settings\R\Pulpit\czyszczenie Loaded Profile: R (Available profiles: R & Administrator) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Alwil Software <====== ATTENTION HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gazeta.pl/0,0.html?p=125 SearchScopes: HKCU - DefaultScope {D289716E-10C6-48A3-AE5D-72738AA62F63} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {D289716E-10C6-48A3-AE5D-72738AA62F63} URL = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} S3 UIUSys; system32\DRIVERS\UIUSYS.SYS [X] CustomCLSID: HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File CustomCLSID: HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension DeleteKey: HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings C:\Documents and Settings\All Users\Dane aplikacji\BucavRaqun C:\Documents and Settings\All Users\Dane aplikacji\tmp C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension EmptyTemp: ***************** Processes closed successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D289716E-10C6-48A3-AE5D-72738AA62F63}" => Key deleted successfully. "HKCR\CLSID\{D289716E-10C6-48A3-AE5D-72738AA62F63}" => Key not found. UIUSys => Service deleted successfully. "HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}" => Key deleted successfully. "HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}" => Key deleted successfully. "HKU\S-1-5-21-1251762338-734992631-2010050143-1004_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}" => Key deleted successfully. HKLM\Software\Mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} => value deleted successfully. HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchSettings => Key Deleted successfully. C:\Documents and Settings\All Users\Dane aplikacji\BucavRaqun => Moved successfully. C:\Documents and Settings\All Users\Dane aplikacji\tmp => Moved successfully. C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension => Moved successfully. EmptyTemp: => Removed 3 GB temporary data. The system needed a reboot. ==== End of Fixlog ====